Slide 32
Slide 32 text
32
© Mandiant, a FireEye Company. All rights reserved.
Bringing the Parts Together (cont.) – Writing Logstash Configs
• Input
• Where is the data?
• How to interpret it?
• Labels
• Flat text, known-structure, or known-input (Twitter, SQLite, RabbitMQ,
ZeroMQ, XMPP, etc.) ?